Expand description
§ic-cipher — block ciphers, stream ciphers, and AEADs
Pure-Rust, no_std, dependency-free implementations of AES (FIPS 197),
the SP 800-38A confidentiality modes, AES-GCM (SP 800-38D), and the
RFC 8439 ChaCha20-Poly1305 suite.
use ic_cipher::Aes256Gcm;
use ic_core::traits::Aead;
let cipher = Aes256Gcm::new(&[0x2a; 32])?;
let mut buf = *b"ship it";
let mut tag = [0u8; 16];
cipher.seal_detached(&[0u8; 12], b"context", &mut buf, &mut tag)?;
cipher.open_detached(&[0u8; 12], b"context", &mut buf, &tag)?;
assert_eq!(&buf, b"ship it");§Backend status
AES computes its S-box algebraically and GHASH multiplies without tables, so neither touches a key-dependent memory address — the cache-timing channel that table-driven AES leaves open is closed by construction.
Three backends sit behind the same traits, chosen by the CPU and never by key material: AES-NI with PCLMULQDQ on x86-64, the ARMv8 crypto extensions behind a feature, and a portable one everywhere else. The portable AES path is bitsliced for encryption — four blocks at a time in transposed form, at roughly the rate of RustCrypto’s fixsliced implementation. Decryption is not bitsliced and runs a byte at a time, which is correct and slow; the modes that move volume (CTR, GCM, GCM-SIV) only encrypt.
ic_ontology::runtime::backend() reports which one is active, so an agent
can decide whether a workload belongs here.
Re-exports§
pub use aes::Aes128;pub use aes::Aes192;pub use aes::Aes256;pub use chacha::chacha20_xor;pub use chacha::ChaCha20Poly1305;pub use chacha::Poly1305;pub use gcm::Aes128Gcm;pub use gcm::Aes192Gcm;pub use gcm::Aes256Gcm;pub use gcm::GcmLimits;pub use gcm_siv::Aes128GcmSiv;pub use gcm_siv::Aes256GcmSiv;pub use keywrap::Aes128Kw;pub use keywrap::Aes128Kwp;pub use keywrap::Aes192Kw;pub use keywrap::Aes192Kwp;pub use keywrap::Aes256Kw;pub use keywrap::Aes256Kwp;pub use modes::cbc_decrypt;pub use modes::cbc_encrypt;pub use modes::ctr_xor;pub use modes::pkcs7_pad;pub use modes::pkcs7_unpad;
Modules§
- aes
- FIPS 197 AES, with a portable constant-time backend and an optional hardware-accelerated one.
- chacha
- RFC 8439 ChaCha20, Poly1305, and the ChaCha20-Poly1305 AEAD.
- gcm
- NIST SP 800-38D Galois/Counter Mode.
- gcm_siv
- AES-GCM-SIV (RFC 8452): authenticated encryption that survives nonce reuse.
- gf
- Constant-time GF(2^8) arithmetic for AES.
- keywrap
- AES Key Wrap (SP 800-38F, RFC 3394 and RFC 5649).
- modes
- NIST SP 800-38A confidentiality modes.
- polyval
- POLYVAL, the universal hash underneath AES-GCM-SIV (RFC 8452 section 3).
Constants§
- AEAD_
IDS - Ontology identifiers for the AEADs this crate provides.
- BLOCK_
CIPHER_ IDS - Ontology identifiers for the raw block ciphers this crate provides.